Senior Manual Ethical Hacker
Bank of America · Chicago, IL · 1 wk ago
EngineeringFull-time
Key Responsibilities
- Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
- Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
- Develop Proof-of-concepts for exploitation.
- Assess the security, effectiveness, and practicality of multiple technology systems.
- Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
- Prepare and present detailed technical information for various media including documents, reports, and notifications.
- Provide clear and practical advice regarding managing risks.
- Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
- Respond to security incidents and provide technical assistance to leadership across the Information Security organization.
Required Skills
- Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment.
- Detailed technical knowledge in at least 5 of the following areas: security engineering, application architecture, authentication and security protocols, application session management, applied cryptography, common communication protocols, mobile frameworks, single sign-on technologies, exploit automation platforms, Web APIs, cloud environments, LLM security, mobile application analysis.
- Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings.
- Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools.
- Experience performing manual code reviews for security relevant issues.
- Experience working with DAST and SAST tools to identify vulnerabilities.
- Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies).
- Experience with vulnerability assessment tools and penetration testing techniques.
- Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction.
- Threat Analysis, threat modelling and SBOM analysis.
- Innovative thinking, threat actor simulation.
- Technology Systems Assessment.
- Technical Documentation.
- Adaptability.
- Collaboration.
- Scenario Planning and Analysis.
- Test Engineering.
- Written Communications.
- Attention to Detail.
- Information Systems Management.
- Issue Management.
- Presentation Skills.
Desired
- CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
- Strong programming/scripting skills.
- Frida
- Binary analysis (disassembly skills)